cvedb.io
CVE-2018-6791
MEDIUM · CVSS 6.8
EPSS exploitation probability: 0%
Published 2018-02-07T02:29:01.453 · Last modified 2026-06-17T02:02:17.547

Summary

An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $() in its volume label is plugged in and mounted through the device notifier, it's interpreted as a shell command, leading to a possibility of arbitrary command execution. An example of an offending volume label is "$(touch b)" -- this will create a file called b in the home folder.

Affected products

kde — plasma-workspace

Does this affect you?

Add your gear to cvedb and we'll alert you only when kde ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.